Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-3325


Improper access control in the GitLab CE/EE API affecting all versions starting from 12.8 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. Allowed for editing the approval rules via the API by an unauthorised user.


Published

2022-10-17T16:15:22.687

Last Modified

2025-05-13T16:15:22.107

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 2.7 (LOW)

Weaknesses
  • Type: Primary
    NVD-CWE-Other
  • Type: Secondary
    CWE-284

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application gitlab gitlab < 15.2.5 Yes
Application gitlab gitlab < 15.2.5 Yes
Application gitlab gitlab < 15.3.4 Yes
Application gitlab gitlab < 15.3.4 Yes
Application gitlab gitlab < 15.4.1 Yes
Application gitlab gitlab < 15.4.1 Yes

References